Mypro

Vendor:

First CVE: Oct 6, 2017 · Active for 8 years

28
Total CVEs
More Total CVEs than 96% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mypro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2017
8 years ago
Most Recent CVE
Jun 11, 2025
408 days ago

CVE Severity & Scoring

Mypro28 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local2 (7.1%)
Network26 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None27 (96.4%)
Unknown0 (0.0%)
Required1 (3.6%)
Privileges Required
Low9 (32.1%)
High0 (0.0%)
None19 (67.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
Apr 27, 20238.861NOYES
An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
Aug 24, 20228.852NONO
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files
May 20, 20189.148NOYES
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information an
Feb 13, 20259.845NOYES
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
Apr 27, 20238.837NONO
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
Feb 13, 20257.534NOYES
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
Jul 2, 20249.831NONO
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
Feb 13, 20259.830NONO
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
Dec 23, 20219.830NONO
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
Dec 23, 20219.830NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
10.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Mypro

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.027.29.0%01